...
SECURITY

Security at DataDock

Our customers process financial reports, tax research, and securities filings through DataDock products. This page describes how we protect that work: our infrastructure, how data is isolated and encrypted, who can access what, and how to reach us about a security concern.

Infrastructure and availability

The Services run on enterprise cloud infrastructure in the United States, deployed across multiple availability zones. Environments for development, staging, and production are separated, and production access is restricted to authorized engineers through audited, credentialed channels. Data is backed up on a regular schedule and restoration procedures are tested.

Encryption

Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard encryption (AES-256). Credentials and API keys are stored hashed or in dedicated secrets management, never in plaintext.

Tenant isolation

Every customer organization operates in a logically isolated tenant. Workspace content is never shared across tenants, never used to serve another customer, and never moved between products without your action. Within a tenant, private workspaces scope research and reporting work to the teams you designate.

Access control and authentication

Access within your organization is role-based: administrators control who can view, prepare, review, and approve work. Sessions are authenticated and expire after inactivity. API access uses scoped keys that can be rotated or revoked at any time. Internally, DataDock personnel access customer data only when required to operate or support the Services, under least-privilege policies with logged access.

Audit logging

Each product records who prepared, reviewed, and approved work, and when. Application and infrastructure logs are collected centrally and monitored for anomalous activity, supporting both your audit needs and ours.

Data handling and AI boundaries

AI assistance in the products operates on authoritative sources and your workspace content, and its outputs pass through human review before they are final. Customer content is not used to train models for other customers. Data handling practices align with applicable privacy frameworks, including GDPR; details are in the Privacy Policy.

Secure development and testing

Code changes go through review before deployment, dependencies are scanned for known vulnerabilities, and security fixes are prioritized ahead of feature work. We engage independent security testing of the products on a recurring basis.

Incident response

We maintain an incident response process covering detection, containment, remediation, and communication. If an incident affects your data, we will notify you without undue delay and as required by law and by your agreement, with the facts we have and the steps being taken.
Report a vulnerability

If you believe you have found a security issue in a DataDock product, email contact@datadock.ai with details and steps to reproduce. We acknowledge reports promptly and keep you informed through resolution. For security questionnaires and data-handling documentation, use the same address.

Enterprise: Enterprise & Institutions

For large organizations and institutions with specialized requirements, this plan offers customizable solutions. Contact us for options like multiple API keys, priority support, redistribution rights, or unlimited data access. Example use cases include:

Scale: Business / Internal Use

Built for organizations leveraging the platform for internal operations, this tier supports data-driven teams and professionals. Common applications include:

Growth: Personal & Startups

Designed for innovators, individual developers, and university researchers, this plan supports small-scale projects and early-stage experimentation. Typical scenarios include:

Explorer:

For testing purposes.
Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.